Head of Cyber Security, AI & Information Governance
Location: Vadodara, Gujarat, India (Hybrid)
Company: Goodcare IT (Part of Webcare Group)
Reporting to: Director of Operations / Executive Leadership Team
About Goodcare IT -
We are seeking an experienced and visionary Head of Cyber Security, AI & Information Governance to lead our global cyber security, AI security, and information governance strategy across Goodcare IT and Webcare Group. Based in Vadodara and reporting to Executive Leadership, this role will work closely with the CTO and cross-functional teams to build a secure, resilient, and compliant technology workplace that supports our international healthcare operations.
The successful candidate will drive the organization's long-term cybersecurity roadmap, strengthen governance, manage cyber risk, protect sensitive healthcare information, and enable the secure adoption of Artificial Intelligence. Combining strategic leadership with strong technical expertise, they will ensure security is embedded across the business, supporting innovation, regulatory compliance, operational resilience, and sustainable global growth.
Key Responsibilities:
1. Cyber Security Strategy & Leadership
Develop, own and continuously evolve the organization's Cyber Security, AI Security and Information Governance Strategy.
Create and maintain a rolling 3–5-year Cyber Security Roadmap aligned with business objectives, technology strategy and international growth plans.
Develop strategic security initiatives that support innovation whilst maintaining regulatory compliance.
Present cyber security risks, strategic initiatives, investment proposals and security performance updates to the Executive Leadership Team.
Develop measurable security objectives, KPIs, KRIs and executive dashboards.
Establish and promote a security-first culture across all business functions.
Lead cybersecurity governance across multiple international jurisdictions.
Monitor emerging cyber threats, technologies, and regulatory developments to ensure the organization remains resilient and prepared.
Build a high-performing cybersecurity capability that supports long-term business growth.
2. Governance, Risk & Information Governance
Lead and continuously improve the organization's Information Security Management, ensuring security, privacy, and governance are embedded throughout every aspect of the organization.
Support compliance with recognized international standards and healthcare regulatory requirements, including:
ISO 27001
ISO 27701
ISO 42001 (Artificial Intelligence Management Systems)
NIST Cybersecurity Framework
Cyber Essentials Plus
GDPR & UK GDPR
NEN 7510
DCB0129
HIPAA (Desirable)
DORA (Desirable)
Responsibilities include
Leading enterprise governance, risk, and compliance programs.
Supporting certification, regulatory assurance, and external audits.
Developing enterprise-wide security policies, standards, frameworks, and governance documentation.
Working collaboratively with Clinical, Technical, Infrastructure, and Compliance teams to ensure information security, privacy,
and clinical risk management principles are embedded throughout the organization.
Supporting healthcare regulatory, clinical safety, and information governance requirements across international operations.
Maintaining enterprise risk registers and security improvement programs.
Conducting third-party supplier security reviews, due diligence, and assurance assessments.
Advising Executive Leadership on regulatory developments, organizational cyber risk, and emerging threats.
3. Technical Security Leadership
Provide strategic and technical leadership across:
Microsoft Azure Security
Microsoft 365 Security
Microsoft Defender Suite
Microsoft Sentinel
Microsoft Entra ID
Microsoft Purview
Cloud Security Architecture
Identity & Access Management (IAM)
Zero Trust Architecture
Network Security
Endpoint Security
Enterprise Database Security
Secure API Architecture
Vulnerability Management
Penetration Testing
SIEM & Security Monitoring
Secure Software Development Lifecycle (SSDLC)
DevSecOps
Incident Response
Business Continuity & Disaster Recovery
Security Architecture Reviews
Encryption & Key Management
Data Loss Prevention (DLP)
Privileged Access Management (PAM)
Work closely with the CTO, technical and Infrastructure teams to ensure Secure-by-Design principles are embedded throughout the software development lifecycle and technology architecture.
4. Data Security & Information Protection
Lead the organization's strategy for protecting patient, clinical and business information throughout its lifecycle.
Responsibilities include
Develop and maintain the enterprise Data Security Strategy.
Ensure the confidentiality, integrity and availability of patient, clinical and corporate information.
Protect databases, cloud environments, storage platforms and business-critical information assets through appropriate security architecture and controls.
Develop standards for database security, encryption, secure configuration, and cryptographic key management.
Ensure appropriate access controls are implemented through Role-Based Access Control (RBAC), Least Privilege and Privileged Access Management.
Develop and oversee Data Loss Prevention (DLP) strategies across Microsoft 365, Azure, and enterprise platforms.
Ensure information is appropriately classified, retained and securely disposed of in accordance with legal, contractual and regulatory requirements.
Monitor and mitigate risks relating to unauthorized access, insider threats and data leakage.
Work closely with the Data Protection Officer and Compliance teams to ensure Privacy by Design principles are embedded throughout systems and services.
Develop monitoring,
auditing and alerting capabilities to detect unusual or unauthorized access to patient records and critical information assets.
Ensure robust backup, cyber resilience and disaster recovery arrangements are maintained for all critical systems and data repositories.
Support secure information sharing with healthcare partners, pharmacies, suppliers, and third-party providers.
5. AI Security & Emerging Technologies:
Lead the organization's AI Security program by:
Developing AI governance policies, standards, and operational frameworks.
Conducting AI-specific security, privacy, and risk assessments.
Supporting the secure adoption of Large Language Models (LLMs) and enterprise AI technologies.
Assessing emerging AI technologies, including frontier AI models such as Anthropic's Mythos-class models and comparable enterprise AI platforms, to understand both their business opportunities and the associated cybersecurity, governance, and information protection risks.
Advising stakeholders on
AI Governance
Prompt Security
Model Risk Management
AI Threat Modeling
Data Privacy
Responsible AI Implementation
Developing secure AI adoption standards and governance frameworks that support innovation while managing organizational risk.
6. Security Operations & Cyber Resilience:
Lead and continuously improve operational security by:
Leading cybersecurity incident response and recovery activities.
Overseeing enterprise vulnerability management.
Managing penetration testing and remediation programs.
Developing executive security dashboards and Key Risk Indicators (KRIs).
Conducting cyber resilience exercises and disaster recovery testing.
Improving organizational cyber maturity through continuous assessment and improvement.
Developing operational security playbooks and incident response procedures.
Managing third-party cybersecurity assurance programs.
Supporting business continuity planning and organizational resilience.
Monitoring emerging cyber threats and recommending proactive mitigation measures.
7. Leadership & Stakeholder Management
Build, mentor, and develop a high-performing cybersecurity capability.
Collaborate closely with Engineering, Infrastructure, Clinical, Compliance, Operations and Product teams.
Work strategically with the CTO and Executive Leadership Team to align cyber security with organizational objectives.
Manage external cyber security vendors, consultants, auditors and strategic partners.
Provide expert technical and strategic advice to Executive Leadership and senior stakeholders.
Develop organization-wide cyber security awareness and education programmes.
Foster a culture of collaboration, accountability and continuous improvement.
Represent the organization with regulators, certification bodies, customers and strategic partners on matters relating to cyber security, AI governance and information governance.
Minimum of 7-9 years' experience within Cyber Security or Information Security.
Interested candidates may apply by submitting their CV to
[email protected] or via WhatsApp at +91 90163 78685.
📌 Head of Cyber Security, AI & Information Governance (Vadodara)
🏢 GoodCare IT Management Services
📍 Vadodara